# Special Categories of Data — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/bijzondere-persoonsgegevens
> Sources are cited per item. Verify against the official texts before relying on them.

Sensitive data requiring enhanced protection (health, biometric, etc.)

## Overview

## Legal Framework

Special categories of personal data are governed primarily by [Article 9 GDPR](/laws/gdpr/art-9), which establishes a general prohibition on processing sensitive data, subject to narrowly defined exceptions. The provision sits atop the general lawfulness requirement in [Article 6(1)](/laws/gdpr/art-6), meaning controllers must satisfy both a lawful basis under Article 6 and a specific exemption under Article 9(2) to process special category data.

Article 9(1) sets out the categories subject to the prohibition:

> "Processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation shall be prohibited."
> — [GDPR Art. 9(1)](/laws/gdpr/art-9#par-1)

The prohibition is lifted only where one of the conditions in Article 9(2) is met. The most commonly relied-upon exception is explicit consent under Article 9(2)(a), which demands a higher standard than the consent basis in Article 6(1)(a). Other exceptions include processing necessary for employment obligations (9(2)(b)), vital interests where the subject cannot consent (9(2)(c)), and legitimate activities of not-for-profit bodies (9(2)(d)). The constitutional underpinning for this heightened protection traces to [Article 21 of the EU Charter](/laws/eu/art-21-38446), which prohibits discrimination on grounds including sex, race, ethnic origin, religion, disability, and sexual orientation.

## Key Developments

Enforcement decisions confirm that the presence of special category data materially raises the stakes for controllers, particularly in breach notification assessments. The EDPB's breach notification guidelines illustrate that when health data is involved, notification to both the supervisory authority and affected data subjects is typically considered necessary:

> "A notification to the SA is considered necessary, as special categories of personal data are involved and the restoration of the data could take a long time, resulting in major delays in patient care."
> — [EDPB Guidelines 01/2021 §39](/posts/38047#seg-39)

Dutch courts have also grappled with the boundary between ordinary sensitive data and special category data. In a livestream enforcement case, the AP took the position that even where data does not formally qualify as special category data under Article 9, its sensitivity can still elevate risk:

> "Hoewel geen bijzondere persoonsgegevens worden verwerkt, is sprake van de verwerking van gevoelige persoonsgegevens die betrekking hebben op betrokkenen en hun privéleven."
> — [Rechtbank, AVG-handhavingszaak livestream ¶10.6](/posts/50406#seg-10.6)

This signals that controllers cannot rely solely on the absence of an Article 9 label to justify lower safeguards — the contextual sensitivity of data remains a risk factor.

## Status of the Debate

This topic is actively contested in court. The core statutory text of Article 9 is settled, but its application to emerging technologies — particularly biometric processing, inferred special category data, and data that reveals sensitive characteristics indirectly — generates divergent judicial outcomes. Courts have not yet definitively resolved whether data that is not inherently special category data but can be used to infer such characteristics triggers the Article 9 prohibition. The boundary between "sensitive" data in a general sense and formally prohibited special category data under Article 9(1) is a live dispute. A CJEU preliminary reference on inferred special category data would provide the clearest resolution.

## Practical Guidance

- **Map your data against Article 9(1) categories precisely.** Data "concerning health" or "revealing racial or ethnic origin" can include inferences drawn from non-sensitive inputs. Document your classification rationale.
- **Secure an Article 9(2) exemption before processing begins.** Explicit consent under 9(2)(a) must be specific, informed, and freely given — bundled consent for multiple processing purposes will not satisfy the standard.
- **Apply heightened security measures.** Article 32 obligations are amplified for special category data; encryption, access controls, and minimisation should be demonstrably calibrated to the elevated risk.
- **Prepare for mandatory breach notification.** As the EDPB guidance confirms, breaches involving special category data will almost always meet the "high risk" threshold requiring both authority notification and direct communication with data subjects.
- **Conduct a DPIA.** Article 35(3)(b) mandates a data protection impact assessment for large-scale processing of special category data. This is not optional and should precede deployment.

## Legislation (full text of key provisions)

### Processing of personal data relating to criminal convictions and offences

*Source: GDPR, gdpr-art-10-en, 2016-04-27 — https://overview.legal/posts/90322*

Processing of personal data relating to criminal convictions and offences or related security measures based on Article 6(1) shall be carried out only under the control of official authority or when the processing is authorised by Union or Member State law providing for appropriate safeguards for the rights and freedoms of data subjects. Any comprehensive register of criminal convictions shall be kept only under the control of official authority.

### Processing of special categories of personal data

*Source: GDPR, gdpr-art-9-en, 2016-04-27 — https://overview.legal/posts/90302*

### Recital 53 — special health data processing conditions

*Source: GDPR, gdpr-rec-53-en, 2016-04-27 — https://overview.legal/posts/91621*

Special categories of personal data which merit higher protection should be processed for health-related purposes only where necessary to achieve those purposes for the benefit of natural persons and society as a whole, in particular in the context of the management of health or social care services and systems, including processing by the management and central national health authorities of such data for the purpose of quality control, management information and the general national and local supervision of the health or social care system, and ensuring continuity of health or social care and cross-border healthcare or health security, monitoring and alert purposes, or for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, based on Union or Member State law which has to meet an objective of public interest, as well as for studies conducted in the public interest in the area of public health. Therefore, this Regulation should provide for harmonised conditions for the processing of special categories of personal data concerning health, in respect of specific needs, in particular where the processing of such data is carried out for certain health-related purposes by persons subject to a legal obligation of professional secrecy. Union or Member State law should provide for specific and suitable measures so as to protect the fundamental rights and the personal data of natural persons. Member States should be allowed to maintain or introduce further conditions, including limitations, with regard to the processing of genetic data, biometric data or data concerning health. However, this should not hamper the free flow of personal data within the Union when those conditions apply to cross-border processing of such data.

### Recital 51 — special categories of personal data protection

*Source: GDPR, gdpr-rec-51-en, 2016-04-27 — https://overview.legal/posts/91617*

Personal data which are, by their nature, particularly sensitive in relation to fundamental rights and freedoms merit specific protection as the context of their processing could create significant risks to the fundamental rights and freedoms. Those personal data should include personal data revealing racial or ethnic origin, whereby the use of the term ‘racial origin’ in this Regulation does not imply an acceptance by the Union of theories which attempt to determine the existence of separate human races. The processing of photographs should not systematically be considered to be processing of special categories of personal data as they are covered by the definition of biometric data only when processed through a specific technical means allowing the unique identification or authentication of a natural person. Such personal data should not be processed, unless processing is allowed in specific cases set out in this Regulation, taking into account that Member States law may lay down specific provisions on data protection in order to adapt the application of the rules of this Regulation for compliance with a legal obligation or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller. In addition to the specific requirements for such processing, the general principles and other rules of this Regulation should apply, in particular as regards the conditions for lawful processing. Derogations from the general prohibition for processing such special categories of personal data should be explicitly provided, inter alia, where the data subject gives his or her explicit consent or in respect of specific needs in particular where the processing is carried out in the course of legitimate activities by certain associations or foundations the purpose of which is to permit the exercise of fundamental freedoms.

### Recital 39 — biometric data processing compliance requirements

*Source: AI Act, aiact-rec-39-en, 2024-06-12 — https://overview.legal/posts/93760*

Any processing of biometric data and other personal data involved in the use of AI systems for biometric identification, other than in connection to the use of real-time remote biometric identification systems in publicly accessible spaces for the purpose of law enforcement as regulated by this Regulation, should continue to comply with all requirements resulting from Article 10 of Directive (EU) 2016/680. For purposes other than law enforcement, Article 9(1) of Regulation (EU) 2016/679 and Article 10(1) of Regulation (EU) 2018/1725 prohibit the processing of biometric data subject to limited exceptions as provided in those Articles. In the application of Article 9(1) of Regulation (EU) 2016/679, the use of remote biometric identification for purposes other than law enforcement has already been subject to prohibition decisions by national data protection authorities.

### Recital 14 — biometric data definition interpretation

*Source: AI Act, aiact-rec-14-en, 2024-06-12 — https://overview.legal/posts/93710*

The notion of ‘biometric data’ used in this Regulation should be interpreted in light of the notion of biometric data as defined in Article 4, point (14) of Regulation (EU) 2016/679, Article 3, point (18) of Regulation (EU) 2018/1725 and Article 3, point (13) of Directive (EU) 2016/680. Biometric data can allow for the authentication, identification or categorisation of natural persons and for the recognition of emotions of natural persons.

### Recital 94 — law enforcement biometric data processing compliance

*Source: AI Act, aiact-rec-94-en, 2024-06-12 — https://overview.legal/posts/93870*

Any processing of biometric data involved in the use of AI systems for biometric identification for the purpose of law enforcement needs to comply with Article 10 of Directive (EU) 2016/680, that allows such processing only where strictly necessary, subject to appropriate safeguards for the rights and freedoms of the data subject, and where authorised by Union or Member State law. Such use, when authorised, also needs to respect the principles laid down in Article 4 (1) of Directive (EU) 2016/680 including lawfulness, fairness and transparency, purpose limitation, accuracy and storage limitation.

### Recital 54 — public interest health data processing safeguards

*Source: GDPR, gdpr-rec-54-en, 2016-04-27 — https://overview.legal/posts/91623*

The processing of special categories of personal data may be necessary for reasons of public interest in the areas of public health without consent of the data subject. Such processing should be subject to suitable and specific measures so as to protect the rights and freedoms of natural persons. In that context, ‘public health’ should be interpreted as defined in Regulation (EC) No 1338/2008 of the European Parliament and of the Council (11), namely all elements related to health, namely health status, including morbidity and disability, the determinants having an effect on that health status, health care needs, resources allocated to health care, the provision of, and universal access to, health care as well as health care expenditure and financing, and the causes of mortality. Such processing of data concerning health for reasons of public interest should not result in personal data being processed for other purposes by third parties such as employers or insurance and banking companies.

### Recital 34 — definition of genetic data

*Source: GDPR, gdpr-rec-34-en, 2016-04-27 — https://overview.legal/posts/91583*

Genetic data should be defined as personal data relating to the inherited or acquired genetic characteristics of a natural person which result from the analysis of a biological sample from the natural person in question, in particular chromosomal, deoxyribonucleic acid (DNA) or ribonucleic acid (RNA) analysis, or from the analysis of another element enabling equivalent information to be obtained.

### Recital 30 — prohibited biometric categorisation systems

*Source: AI Act, aiact-rec-30-en, 2024-06-12 — https://overview.legal/posts/93742*

Biometric categorisation systems that are based on natural persons’ biometric data, such as an individual person’s face or fingerprint, to deduce or infer an individuals’ political opinions, trade union membership, religious or philosophical beliefs, race, sex life or sexual orientation should be prohibited. That prohibition should not cover the lawful labelling, filtering or categorisation of biometric data sets acquired in line with Union or national law according to biometric data, such as the sorting of images according to hair colour or eye colour, which can for example be used in the area of law enforcement.

## Case law

### NSS - 1 As 183/2023-62

*Source: Supreme Administrative Court, 2026-08-04 — https://overview.legal/posts/184683 — original: https://gdprhub.eu/index.php?title=NSS_-_1_As_183/2023-62*

Facts — OAKS Consulting s.r.o. (the company) provided consulting services concerning market access conditions for medicinal products and medical devices. Pursuant to the Czech Act on Free Access to Information, it requested information from the General Health Insurance Company of the Czech Republic concerning the treatment of patients with iron deficiency and related conditions for the period from 1 January 2010 to 31 October 2017. The request covered 183 types of diagnoses, 18 types of medical procedures, 96 DRG codes and 13 types of medications. The company stated that it wished to analyse how specific diagnoses were treated, the number of patients treated, and the frequency of related medical procedures, in order to compare clinical practice against the relevant theoretical background. The public health insurer rejected the request on the grounds that granting it would require the creation of new information. Following an appeal by the company, the Prague Municipal Court overturned the decision. The public health insurer provided then the company with five separate tables regarding the diagnoses, diagnoses in conjunction with medical procedures, the DRG codes and prescribed medications. It aggregated the parameters of the provided data as follows: five-year age groups, dates were given only at the monthly level, and healthcare providers were classified into broad geographic regions. However, it refused to add a unique random identifier which would allow linking the individual records and tables pertaining to the same patient. The public health insurer considered that providing the code would result in the disclosure of special categories of personal data. The company lodged a complaint with the Czech DPA (UOOU), which rejected it. The company filed another appeal with the Municipal Court of Prague, which dismissed the appeal. It ruled that the combination of factors such as gender, year of birth, the time and place of care, diagnoses, medications, and medical procedures could, with the addition of other information, lead to the identification of specific patients. According to the court, the random identifier would result in pseudonymisation rather than anonymisation, so the information would remain personal data pursuant to Article 4(1) GDPR. The Municipal Court also relied on modern technical capabilities for linking different sources and on the availability of a large volume of information in the media and on social media. It cited the CJEU’s decision in the Breyer case (C-582/14), according to which in order to determine whether a person is identifiable, account must be taken of all the means that could reasonably be used, both by the controller and by any other person, to identify that person. It did not follow the approach taken by the General Court in Case T-557/20 (SRB v. EDPS), which the company had cited. It ruled that the data were pseudonymised and that the requested information could not be disclosed in its entirety. The company filed a cassation appeal with the Supreme Administrative Court, arguing that the information had been anonymised. It alleged that the addition of a random code with no independent meaning would not alter their anonymous nature. It claimed that the Municipal Court had not explained what specific additional information could be used to identify the patients and had relied on hypothetical scenarios. The company stated that it was objectively impossible to obtain such data through other requests in a detailed and non-aggregated form. It also argued that iron deficiency was not a rare disease, but was associated with a large number of patients and various conditions and that the data had undergone both randomisation and generalisation so the risk of identification was therefore low. Finally, the company emphasized that the tables without the random identifier could not be used effectively for the intended analysis. It further argued that the DPA and the Municipal Court had not adequately balanced the right of access to information against the right to the protection of personal data. The DPA argued that the random identifier constituted personal data when considered in conjunction with the health data to which it would be linked. It stated that the concept of personal data was not limited to information that directly identifies an individual nor did it require that all necessary additional information be held by the same entity. Replacing direct identifiers with a code did not anonymise the data, but made it pseudonymised. Moreover, it argued that certain categories contained a relatively small number of records and that combining them with other data could make it possible to select and identify a specific insured person and their treatment history. It further argued that, even if identifiability was relative, it should be assessed in relation to all potential information applicants and their ability to obtain contextual information. The Supreme Administrative Court stayed the proceedings in the case pending the CJEU’s decision in Case C-413/23 P (EDPS v. SRB). After the judgment was issued, the company argued that whether the data were pseudonymised or anonymised should be assessed in relation to the specific recipient of the data and the means that it could reasonably use. It stated that it did not have any means of re-identification and that only specific and practically available cross-referencing possibilities should be taken into account. Holding — The court relied on Case C-413/23 and noted that pseudonymised data under Article 4(5) GDPR does not automatically constitute personal data in relation to every person. Therefore, it examined whether the company had lawful means that could reasonably be expected to be used to identify the patients directly or indirectly. The court found that the tables, without the random identifier, did not allow for the identification of specific insured individuals. It held that the requested random identifier would link the records from the different tables and allow for the aggregation of information on the diagnoses, medical procedures, hospitalizations, and medications for the same patient during the eight-year period. Certain combinations of these data, along with age group, gender, and region, could be unique and allow for the identification of patients using information from public sources. It pointed out that although iron deficiency was a very common diagnosis and some tables contained a very large number of entries, other categories were not sufficiently generalised. According to the court, in certain cases, such as rare diseases, unusual treatment combinations, or particularly young or old age, knowing even a few details about a person could make it possible to identify the corresponding record. The risk was not negligible, given that information about a person’s age, gender, hospitalization, diagnosis, or treatment could be available in the media or on social media. Consequently, the court held that adding the random identifier, in conjunction with the data already provided, would make the dataset personal data in relation to the company under Article 4(1) GDPR, including health data falling under Article 9 GDPR. The court clarified that classifying the information as personal data was not sufficient in itself to reject the request. It noted that the right of access to the information must also be balanced against patients’ right to privacy through an assessment of suitability, necessity and proportionality. It determined that the decision not to provide the random identifier was appropriate for the protection of privacy, because without it, it was impossible to link the tables and identify individual patients. It was also deemed necessary because the company insisted on receiving that specific code along with the existing tables and there was no other procedure that would constitute a lesser infringement of its right to information. The court also recognized the public interest in accessing information related to the operation of the healthcare system, but ruled that this did not outweigh the need to protect the detailed health data of potentially hundreds of thousands of insured individuals. It concluded that the refusal to provide the code was therefore proportionate. The Supreme Administrative Court therefore upheld the Municipal Court’s ruling, but partially corrected its reasoning regarding the relative nature of identifiability and the need to conduct a proportionality review. It dismissed the appeal.

### CJEU - C‑769/22 - European Commission v Hungary

*Source: GDPRhub, 2026-07-24 — https://overview.legal/posts/158432 — original: https://gdprhub.eu/index.php?title=CJEU_-_C‑769/22_-_European_Commission_v_Hungary*

Facts — The background In 2021 Hungary adopted "Law LXXIX of 2021 adopting stricter measures against persons convicted of paedophilia and amending certain laws for the protection of children" ("the amending law"). The law introduced a number of rules to restrict the access of minors to content portraying or promoting gender identities that do not correspond to the sex assigned at birth, sex reassignment or homosexuality. The law also introduced new rules for access to public documents, requiring public bodies to allow broad access to information about individuals convicted of sexual offences against children. The alleged purpose of the law was to protect minors. In 2021 the Commission sent a formal letter to Hungary contesting the amending law's compliance with EU law. After some unproductive back-and-forth, the Commission escalated the case to the CJEU, requesting the CJEU to declare the amending law incompatible with EU law. The European Commission filed four pleas, claiming that Hungary violated of a long list of provisions from primary and secondary EU law . Only the Commission's fourth plea invokes data protection law- specifically, Article 8(2) of the EU Charter of Fundamental Rights (CFR) ("Protection of personal data") and Article 10 GDPR ("Processing of personal data relating to criminal convictions and offences"). The fourth plea: Article 10 GDPR The alleged violation of the GDPR relates to the amended law's rules on access to information about individuals convicted of sexual offences against children. The law amended the "Law on the criminal record system" and made documents about sexual offences accessible to a broad audience. Under the new rules, any adult who is either a relative or a guardian of a minor ("authorised person"), has the right to access and share information about individuals convicted of sexual offences against children (the data subjects) from bodies with access to registered data. The Commission claimed that the amended law failed to specify with sufficient clarity who is authorised to submit a data request and, therefore, did not provide sufficient guarantees for the rights and freedoms of data subjects regarding the conditions of access to their personal data. On these grounds, the Commission claimed that the amended law infringed Article 10 of the GDPR (as well as Art. 8(2) CFR). In its defense, Hungary argued that the law accurately identified "authorised persons" when read in light of the definition of "relatives" in the Hungarian civil code. Additionally, Hungary claimed that there were two additional criteria access to personal data under Hungarian law: the authorised person must consider the relevant data to be probably necessary, and it must be disproportionately difficult for them to access the subjects' data if they are not disclosed. In other words, Hungary argued that when interpreted correctly, Hungarian law provided for three cumulative criteria for the disclosure of data about convictions for sex offences against children: (i) the disclosure was requested by an authorized person (i.e. "any adult who is either a relative of, or educates, supervises or cares for, a person who has not attained 18 years of age"- where "relative" was to be understood in the well-defined sense of Hungarian civil law); (ii) the disclosure was probably necessary to keep the minor safe; (iii) it was disproportionately difficult for the authorized person to access the data otherwise. Hungary claimed that these criteria were clearly defined and provided sufficient safeguards for data subjects. On this basis, Hungary argued that the amended law complied with Article 10 GDPR and 8(2) CFR. Advocate General Opinion — AG Cápeta clarified that, according to CJEU case law, the GDPR did not impose an absolute ban on the disclosure of personal data from public authorities. The GDPR did, however, require a balancing between the purpose of such disclosures, and the rights and freedoms of data subjects. In particular, the disclosure of personal data regarding criminal convictions, required strict justification and clear legal safeguards, because of the sensitive nature of such data. In the case at hand, the AG conceded that the data disclosure pursued an important public interest (the protection of minors). So, the question was whether the amending law correctly balanced this interest against the right to data protection. The AG opined that the amending law failed to do so and exceeded what was strictly necessary to protect minors, for two reasons. First, the AG agreed with the Commission that the notion of "authorised persons" was too broad and unclearly defined under the amending law, even when the amending law was interpreted in light of domestic civil law. In this regard, the AG pointed to the CJEU case law on the access to personal data from national authorities: in order to satisfy the requirement of proportionality, national law that allowed for such access "must lay down clear and precise rules governing the scope and application of the measure in question and imposing minimum safeguards". The AG further opined that such criteria would also apply to access from private citizens, as in the case at hand. Second, the AG considered that requirements (ii) and (iii) (i.e.: the probable necessity of the disclosure, and the difficulty of otherwise accessing the data) were overly generic and were to be assessed by the authorized person themselves. The AG argued that such a self-declaratoty regime lent itself to abuse and deprived the disclosing body of any control over the necessity and proportionality of the disclosure. For this reason, the AG opined that the amending law failed to provide the required safeguards for data subjects. On these grounds, the AG opined that the amended law was disproportionate and violated Article 10 GDPR as well as Article 8(2) CFR. Holding — The court first noted that one of the objectives of the GDPR is to ensure a high level of protection of data subjects’ fundamental rights and freedoms, in accordance with Article 1 GDPR and Article 8(1) CFR. Therefore, any processing of personal data must be lawful, in accordance with Articles 5(1)(a) and 6(1) GDPR. In addition, any legal basis other than consent (Article 6(1)(a) GDPR) must be interpreted restrictively. The court then assessed whether the processing was lawful under Article 6(1)(e) and 86 GDPR. Article 6(1)(e) GDPR provides for a legal basis based on public interest or in the exercise of official authority vested in the controller. In the case of disclosing this data, Article 86 GDPR states that this may be done to reconcile public access to official documents with the right to the protection of personal data. The court stated that, in principle, the processing of data related to criminal convictions (including its disclosure) could be lawful under Article 6(1)(e) and 10 GDPR. However, Article 10 GDPR makes the processing subject to additional restrictions (for example, the processing must provide for appropriate safeguards). In addition, limits to the fundamental rights to privacy and data protection must respect the essence of the fundamental right and be proportionate, in accordance with Article 52(1) CFR. This is especially relevant in this case, as data related to criminal convictions is particularly sensitive and its processing can be a particularly serious interference with data subjects’ fundamental rights. The court followed the reasoning of the AG in stating that the protection of minors was an important public interest. However, the court considered the amending law incompatible with Article 10 GDPR. The law was not sufficiently precise, particularly in defining the concept of “authorised person”. The court considered that the processing was not limited to what is strictly necessary, as the circle of persons potentially entitled to submit a request was too broad. Finally, the court concurred with the AG, and stated that the amending law was not proportionate. This is because it relied on the person requesting the data to justify the need to access it. Therefore, the amending law did not provide for appropriate safeguards by relying on the self-declaration regarding the necessity and proportionality of accessing the data. The court concluded that the amending law did not meet the requirements under Article 10 GDPR, meaning it could not justify its processing under Article 6(1)(e) GDPR. With this, Hungary had failed to fulfil its obligations under Article 10 GDPR and Article 8(2) CFR.

### CJEU - C‑474/24 - NADA Austria and Others

*Source: GDPRhub, 2026-07-24 — https://overview.legal/posts/108989 — original: https://gdprhub.eu/index.php?title=CJEU_-_C‑474/24_-_NADA_Austria_and_Others*

Facts — Several data subjects were subject to suspension proceedings by the Austrian Anti-Doping Legal Commission (ÖADR). Under Austrian law, the National Anti-Doping Agency (“NADA”) publishes the names of persons who have been suspended on its website. For the duration of the suspension, the website includes information such as the athlete’s name, sport practised, infringement of anti-doping rules, and the duration of the penalty. The ÖADR publishes the same information in a press release, with the addition of the prohibited substances involved. For this summary, both authorities are referred to as the controllers. The data subjects filed a complaint with the DPA on the grounds that the controllers refused their request to cease displaying their names and practised sports. They also argued that the controllers were processing sensitive data within the meaning of Article 9 and 10 GDPR, and that the undifferentiated publication system was incompatible with Article 6(3) GDPR. The DPA dismissed the complaint. In particular, one of the data subjects’ complaints was rejected on the grounds that the relevant data had not been published yet. The data subjects appealed the decision to the Federal Administrative Court (BVwG). The controllers argued that publishing the information in their website was lawful, as it was based on the legal bases of legal obligation (Article 6(1)(c) GDPR) and public interest (Article 6(1)(e) GDPR). The BVwG stayed proceedings and requested a preliminary ruling from the CJEU. The BVwG referred the following questions: Does the GDPR apply to the making information relating to athletes’ anti-doping violations publicly available through websites? If yes: Does information that an individual has committed a specific anti-doping violation fall under the scope of data relating to health within the meaning of Article 9 GDPR? Does the GDPR preclude national legislation from publishing the information mentioned above, if it does not make it possible to infer health data of the person concerned? Does the GDPR require a balancing test between the interests of the data subject and the interest of the general public of being informed of anti-doping violations every time anti-doping violations will be published? Does information that an individual has committed a specific anti-doping violation fall under the scope of data relating to criminal convictions within the meaning of Article 10 GDPR? If yes, must the decisions of the authority processing this data be subject to judicial review? Is filing a complaint before the processing takes place (but was processed during the proceedings) permissible? Or does it become permissible provided that at the time of the complaint there were specific indications that the processing was imminent or would take place in the near future? Advocate General Opinion — The AG gave his opinion on each question separately, with the exception of the third and fourth questions that were answered together. Question 1: Does the GDPR apply to the making information relating to athletes’ anti-doping violations publicly available through websites? — The AG first considered that the GDPR was applicable to this case. Under Article 2(2)(d) GDPR a situation falls outside of the scope of the GDPR when data is processed for the prevention, detection or prosecution of criminal offenses. This is because the Law Enforcement Directive (LED) applies. According to the AG, the GDPR may apply even if personal data relating to criminal convictions is processed if the controllers are not “competent authorities” within the meaning of Article 3(7) LED. If the controllers were competent authorities, the referring court would have to decide if the GDPR applies. The main question the AG addressed is whether the exception under Article 2(2)(a) GDPR applies, meaning the processing falls outside the scope of Union law; here, the AG noted that the exceptions are interpreted narrowly, and may only apply to activities intended to safeguard national security or activities classified in the same category. The AG concluded that the aim of combating anti-doping is not related to national security. The exception did not apply even if the activity fell under the competence of a Member State. Therefore, the GDPR was applicable. Question 2: Does information that an individual has committed a specific anti-doping violation fall under the scope of data relating to health within the meaning of Article 9 GDPR? — The AG first highlighted the sensitive nature of Article 9 GDPR data, which must be interpreted broadly. The AG also noted that the legal basis of the controller does not influence whether the data falls under the scope of health data. Beyond a medical context, the AG opined that the determining factor is whether it is possible to draw inferences about the health status of the data subject. In this case, the AG agreed with the reasoning of the DPA that only specific information relating to the infringements should be considered health data. This is because not all data revealed information related to the data subjects’ health. Specifically, the information regarding the anti-doping tests and its analysis should be considered health data. The AG noted that, while the name of the substance itself may not reveal information on health status, it may be possible to make indirect inferences. However, if the name is not included, the link to the health status of the data subject would be too indirect to fall under the scope of health data. Questions 5 and 6: Does information that an individual has committed a specific anti-doping violation fall under the scope of data relating to criminal convictions within the meaning of Article 10 GDPR, and must the decisions of the authority processing this data be subject to judicial review? — The AG first noted that the GDPR does not prohibit processing this data, but rather subjects it to enhanced scrutiny. The AG assessed whether the processing fell under the scope of Article 10 GDPR based on the three “Engel” criteria in ECtHR case Engel and Others v. the Netherlands. Anti-doping offenses under national law do not fall under the “criminal” classification according to Article 10 GDPR. However, the AG opined that article 10 GDPR applies if the convictions have a punitive purpose and have a degree of severity equivalent to a criminal penalty. This is a matter for the BVwG to decide. In terms of judicial review, the AG stated that the authority at issue is an “official authority” within the meaning of Article 10 GDPR. The wording itself of Article 10 GDPR does not provide for judicial review. However, the AG opined that it must be possible for an act following a decision by an official authority to be subject to judicial review. This is in light of Article 79(1) GDPR and a contextual interpretation of Article 10 GDPR. Questions 3 and 4: Does the GDPR preclude national legislation from publishing the information mentioned in the facts, and does it require a balancing test every time anti-doping violations will be published? — The AG considered, in essence, whether Articles 5(1)(a) and (c), and Article 6(3) GDPR precluded the controllers to publish the data concerned under legal obligation. The AG also considered whether the GDPR requires a case-by-case balancing of interests, or whether the proportionality test provided by the legislator is sufficient. The AG noted that the aim to deter athletes and prevent circumventing of anti-doping rules are legitimate public interest objectives in the context of combating doping in sport. Making this information public online is appropriate in order to achieve the public interest aims, with the exception of referring to the prohibited substance in question. According to the AG, this was not expressly provided for by national law, and is not required to achieve the public interests involved. However, the AG considered the publication of the personal data involved a serious interference with the fundamental rights of the data subjects. While national law provided exceptions on the publication of data (e.g. amateur athletes or vulnerable persons), the AG opined that the publication of personal data for an unlimited amount of time could be considered excessive. Therefore, the AG concluded that making this information publicly accessible is only permitted as long as it is proportionate. Finally, the AG opined that a case-by-case analysis is necessary, as the controllers must comply with data minimisation and accountability principles under the GDPR even if they are designated by national law. Question 7: Is filing a complaint before the processing takes place permissible? — Here, the AG stated that the wording of the GDPR does not seem to preclude a priori a precautionary or preventative approach by the supervisory authorities in handling complaints. Restricting the powers of a DPA to decide on cases involving processing that has already taken place would go against the objectives of the GDPR. Nonetheless, the alleged infringement of the GDPR must be appropriate, and the processing in question cannot be purely hypothetical. In this case, it would be impossible for a controller to erase data that has not been disclosed yet, unless the complaint is interpreted as seeking to prevent the data from being published. The AG stated that it is a matter for the BVwG to decide. The AG noted that the complaint would be inadmissible if it was based on Article 17 GDPR even if the processing is imminent. However, the AG opined that a complaint requesting injunctive relief is potentially admissible under the GDPR and Austrian law in the event of a threat of imminent unlawful interference with data subjects’ rights under the GDPR. This includes requesting the DPA to review a restriction of processing based on Article 18 GDPR before the start of the processing or if the processing has started, as long as the processing is not purely hypothetical. Finally, the AG considered whether a complaint could become admissible a posteriori. Here, the AG opined that it is a matter of the national law system to settle the question, while complying with the principles of effectiveness and equivalence. Holding — The Court held that the GDPR applied to the publication of information concerning anti-doping infringements. Such processing did not fall within the exception under Article 2(2)(a) GDPR, even if anti-doping policy primarily falls within Member State competence. Information that a data subject infringed anti-doping rules and was banned from competitions does not, in principle, constitute health data under Article 9 GDPR. However, it may do so where the publication identifies a prohibited substance or method and, together with other information, allows conclusions to be drawn about the data subject’s health. The Court accepted that combating doping and protecting the fairness and integrity of sport constitute objectives of general interest. Nevertheless, publishing athletes’ identities and sanctions online constitutes a serious interference with their rights. National legislation may therefore require such publication only where the controller can assess, in each case, whether the content and duration of the publication are necessary and proportionate. Publication should not continue longer than strictly necessary and may be disproportionate where a sanction is lengthy or lifelong. The Court also held that Article 10 GDPR did not apply, as the anti-doping infringements formed part of a disciplinary regime and were not criminal in nature. Finally, Article 77 GDPR allows a data subject to lodge a complaint before processing takes place where there are specific indications that the processing is imminent and not merely hypothetical. The DPA must assess the substance of such a preventive complaint.

### CJEU - C‑209/23 - RRC Sports

*Source: GDPRhub, 2026-07-16 — https://overview.legal/posts/144028 — original: https://gdprhub.eu/index.php?title=CJEU_-_C‑209/23_-_RRC_Sports*

Facts — Fédération internationale de football association (FIFA) is a Switzerland-based non-profit that acts as the global governing body for football. A large number of football clubs and national football associations are member of FIFA and bound by its regulations. In January FIFA published the FIFA Football Agent Regulations (FFAR). FFAR regulated the conduct of player’s agents. In particular, FFAR provided maximum limits to agents’ remuneration and prohibited specific types of contractual arrangements between clubs, agents, and agencies. In order to ensure compliance with these rules, Article 12 FFAR required agents to disclose certain information to FIFA. In particular, agents had to disclose: Information about any agreement with a client, other than a representation agreement; Information on any arrangement between agents to cooperate in the provision of their services, or to share the revenue or profits of their services; Information about their relationship with agencies, including the names of all of the agency’s employees. Additionally, FIFA would make the information available to a number of stakeholders including agents, players, and football clubs. Three applicants (an agent, a company acting as a players’ agent, and the Vice-President of a players’ agents’ associations) challenged FFAR in the Regional Court of Mainz (Germany). The Court referred four questions to the CJEU for a preliminary ruling. In essence, the Court asked the CJEU whether the FFAR was compatible with Articles 101 TFEU (prohibition on cartels), 102 TFEU (prohibition on abuse of a dominant position), 56 TFEU (freedom to provide services), and 6 GDPR (legal bases for processing personal data). With regards to Article 6 GDPR specifically, the referring court essentially asked whether there was a lawful basis under the GDPR for a collection of personal data, such as required under the FFAR’s mandatory disclosure rules. Advocate General Opinion — The referring question did not specify what legal basis had to be examined in order to assess the compatibility of FFAR disclosures with the GDPR. However, the AG opined that interest under Article 6(1)(f) was the relevant legal basis, based on the nature of the FFAR rules and on other information on the order for reference. Therefore, the AG focused on the legal basis of legitimate interest exclusively. The AG recalled that the mandatory disclosure under FFAR were compatible with the GDPR if they met three cumulative requirements: They genuinely pursued an interest worthy of protection; They were limited to what was strictly necessary to that end; They did not place an intolerable burden on the data subjects as regards their right to privacy and their financial interests. The AG opined that in the case at hand, the processing of personal data pursued an interest worthy of protection (that is, FIFA’s interest in ensuring that the conduct of agents was consistent with the core objective of the football transfer systems, and other objectives related to the good functioning of the player market). However, the AG was more cautious about the other two requirements. With regards to the requirement of necessity, the AG noted that FFAR required the collection of a substantial amount of personal data, including delicate data about agents’ remuneration and contractual agreements. Additionally, FIFA would not only receive the data but also make it available to stakeholders such as clubs, players, and player’s agents. The AG opined that such a broad collection and disclosure of personal data could, to some extent, exceed what was strictly necessary to pursue FIFA’s legitimate interest. In that regard, the AG stressed that FIFA should explain to the referring court why the collection and disclosure of the data were necessary, in relation to each type of information. With regards to the balancing of interests, the AG opined that agents operate within a regulatory framework and, therefore, have a reasonable expectation that FIFA would process their data as a regulatory body. In the AG’s view, this expectation could weight favorably on the balancing of legitimate interest. At the same time, the AG opined that the availability of agents’ personal data to both competitors and potential clients, could financially harm agents and erode trust in agent-client relationships. Holding — The CJEU held that processing based on Article 6(1)(f) GDPR is lawful only where three cumulative conditions are met. First, the controller or a third party must pursue a legitimate interest. Second, the processing must be necessary for that interest. Third, the interests or fundamental rights and freedoms of the data subject must not override the legitimate interest pursued. Regarding the information agents were required to submit through the controller’s digital platform under Article 16 FFAR, the Court considered that ensuring compliance with the regulatory framework governing football agents could constitute a legitimate interest. This was conditional on the underlying obligations being compatible with EU and national law. The Court found that the information required under Article 16 FFAR appeared capable of identifying attempts to circumvent rules on representation, remuneration and conflicts of interest. The processing could therefore be adequate, relevant and limited to what was necessary. However, the referring court had to determine whether equally effective but less intrusive measures were available and assess any additional information requested through the platform whose precise scope was not defined in the regulations. The processing under Article 16 FFAR could therefore be compatible with Article 6(1)(f) GDPR, subject to verification by the referring court. Regarding Article 19 FFAR, the Court distinguished between the different categories of information disclosed by the controller. The publication of agents’ names and contact details, the identity of their clients, the duration and exclusivity of representation agreements and the services provided could pursue legitimate interests such as establishing professional and ethical standards, protecting clients from unethical conduct and improving transparency. Since the information concerned professional activities within a regulatory framework known to the persons involved, this processing could satisfy the balancing test under Article 6(1)(f) GDPR. By contrast, publishing detailed information about every transaction involving an agent, including the service fees paid, was not limited sufficiently. The Court held that agents and clients did not need access to detailed information about all transactions involving their competitors to comply with the regulations. The indiscriminate disclosure of this information therefore infringed the data minimisation principle under Article 5(1)(c) GDPR and was not necessary under Article 6(1)(f) GDPR. The Court also examined the publication of sanctions imposed on agents and clients. It accepted that publication could, in certain circumstances, deter misconduct, restore confidence in the market and allow persons harmed by an infringement to become aware of it. Nevertheless, Article 19 FFAR required the publication of every sanction without considering its seriousness, the harm caused, its relevance to market confidence or the time elapsed since the infringement. The regulation also did not provide for the information to cease being available after a defined period. The blanket publication obligation therefore did not appropriately balance the controller’s interests against the data subjects’ rights under Articles 7 and 8 CFR. Moreover, where a sanction contained personal data relating to criminal convictions or offences, Article 10 GDPR applied. In the absence of authorisation under EU or Member State law and supervision by a public authority, the controller could not process such data. The Court consequently held that Article 6(1)(f) GDPR precluded regulations adopted by an international sports federation insofar as they required the disclosure and publication of: every sanction imposed on agents or their clients; and detailed information concerning all transactions involving agents. The Court did not impose a fine or order any specific corrective measure. It provided an interpretation of EU law for the referring court, which remained responsible for resolving the underlying dispute and verifying the relevant factual and legal conditions.

### BVwG - W137 2327171-1

*Source: Federal Administrative Court, 2026-07-08 — https://overview.legal/posts/184712 — original: https://gdprhub.eu/index.php?title=BVwG_-_W137_2327171-1*

Facts — The controller, an assistant professor at a private university (the appellant), was engaged in an employment dispute with her university employer before a labour and social court. The data subject, a senior legal counsel employed by the university gave testimony as a witness in that employment proceeding. On 23 January 2025, the labour and social court ruled in the controller's favour, finding that her employment relationship continued beyond the university's purported termination date. The judgment referred to the data subject several times by her academic title and surname in connection with her witness testimony. In April 2025, the controller published the unredacted judgment in full, including the data subject's title and surname on social media. She shared a downloadable link (first via Dropbox, later via Adobe) on her public Facebook profile and in a closed Facebook group of around 230 members connected to the university community. The files were later removed by Dropbox and Adobe after the data subject reported them. The data subject's full first name and additional details could also be found by combining her academic title and surname with the university's name in a Google search, which surfaced her LinkedIn profile. The data subject filed a complaint with the Austrian DPA, arguing that the controller had no justification for naming her and had drawn her into a public dispute with her employer. The controller argued that the judgment concerned matters of wider relevance to university staff, that the Facebook group was closed and that the data subject's name and role were already public via the university directory and LinkedIn. On 15 October 2025, the DPA upheld the complaint, finding that the controller had violated the data subject's right to secrecy under §1(1) of the Austrian Data Protection Act (DSG) by publishing the judgment without a legal basis. The DPA found that a legitimate interest existed in principle, but that both publications were excessive as the judgment was made accessible to an uninvolved and disproportionately wide audience and that disclosing the data subject's name was not necessary to achieve the controller's stated purpose of informing colleagues in similar situations. The DPA noted that publishing the judgment with the data subject's name redacted would have been an equally effective, less intrusive alternative. The controller appealed, arguing that the data subject had no protectable secrecy interest because she had participated in the proceeding in a public professional capacity and had made comparable information about herself public on LinkedIn and that the DPA had failed to weigh her freedom of expression rights under Article 10 ECHR against the data subject's secrecy interest. Holding — The court dismissed the appeal in full and confirmed the DPA's decision. First, the court rejected the controller's argument that no protectable secrecy interest existed because the data subject had acted in a professional capacity. It held that, under settled national case-law, appearing in a professional role does not by itself remove a person's right to secrecy under §1(1) DSG. Second, applying the three-part test for legitimate interest under Article 6(1)(f) GDPR, the court accepted that the controller had, in principle, a legitimate interest in informing colleagues in comparable employment situations about the judgment. However, it held that publishing the data subject's surname failed the necessity requirement under this test and therefore also breached the data minimisation principle under Article 5(1)(c) GDPR. The court noted that the data subject was a witness testifying about legal matters, not the person responsible for the controller's employment contract and that naming her added nothing to the comprehensibility or persuasive value of the information the controller sought to share. Because necessity was lacking, the court found it unnecessary to conduct any further balancing of the parties' respective rights. Third, the court rejected the controller’s argument that her freedom of expression justified the full disclosure of the judgment, for which she relied on the CJEU’s judgment in Case C-345/17 (Buivids). The court held that Buivids concerned whether processing could be regarded as being carried out solely for journalistic purposes, whereas there was no indication of journalistic activity in the present case. It further held that §9 DSG, which implements Article 85 GDPR in relation to journalistic activity, was therefore inapplicable. In any event, the court stated that §9 DSG does not entirely override the principle of proportionality but establishes a different standard for balancing the competing interests. Finally, the court agreed with the DPA that redacting the data subject's name and title would have been an equally effective and only minimally burdensome alternative that would not have undermined the controller's informational purpose and held that the controller had not plausibly explained why such redaction would have been insufficient. The court accordingly found no unlawfulness in the DPA's decision and dismissed the appeal. It declared that an appeal on points of law (Revision) was not admissible, since the case did not raise a legal question of fundamental importance and was consistent with existing case-law.

### Audiencia Nacional upholds €2M AEPD fine against Amazon Flex for criminal-record checks

*Source: National Court, 2026-07-08 — https://overview.legal/posts/184679 — original: https://gdprhub.eu/index.php?title=AN_-_SAN_2996/2026*

Facts — Unión General de Trabajadores (UGT), a trade union, lodged a complaint with the DPA (AEPD) against Amazon Road Transport Spain, S.L., the controller. Applicants wishing to work within the Amazon Flex delivery programme were required to provide a certificate confirming that they had no criminal record. The certificates and other application documents were processed by external processors responsible for the preliminary screening of candidates. The controller considered this requirement necessary to protect its customers and ensure the security of the programme. Delivery drivers transported packages directly to private residences and had access to customers’ addresses, telephone numbers and information that could reveal aspects of their habits. They could also be entrusted with packages of significant value. On 10 February 2022, the DPA imposed a €2 million fine on the controller for an infringement of Article 6(1), in conjunction with Article 10 GDPR, as well as Articles 10 and 71 LOPDGDD. The DPA considered that a certificate showing the absence of criminal convictions still constituted personal data relating to criminal convictions and offences. Consequently, it held that candidates’ consent could not legitimise the processing without a specific authorisation under Union or national law. The controller appealed the decision before the Audiencia Nacional, the appeal court. It argued that a certificate confirming the absence of criminal records did not fall within Article 10 GDPR and referred to previous cases in which the DPA had accepted similar requirements for certain professional activities. Holding — The Court granted the appeal and annulled the DPA’s decision and the €2 million fine. First, the Court held that Article 10 GDPR must be interpreted strictly, particularly in administrative sanctioning proceedings, which are governed by the principle of minimum intervention and the prohibition of extensive interpretations against the alleged infringer. The Court distinguished between processing information concerning existing criminal convictions or offences and processing a certificate confirming that the person has no criminal record. In its view, Article 10 GDPR expressly covers personal data relating to criminal convictions and offences, but not information concerning their absence. The Court considered that a negative criminal record certificate contains favourable information regarding a person’s conduct. Therefore, processing such a certificate does not amount to processing specially protected criminal-offence data under Article 10 GDPR. As a result, the consent provided by candidates was not invalid merely because no Union or national law specifically authorised the processing under that provision. The Court distinguished the case from situations involving direct access to criminal-record databases or the creation of files containing adverse information. It also distinguished previous employment-law judgments concerning employers requesting criminal records. Although requiring such certificates could be unlawful or abusive under employment law, this did not necessarily mean that the conduct was sanctionable under data protection law. Nevertheless, the Court clarified that processing negative criminal record certificates remained subject to the general GDPR requirements, particularly the principles under Article 5 GDPR and the need for a valid legal basis under Article 6(1) GDPR. In this regard, the Court found the controller’s reasons sufficient to consider the processing legitimate. Amazon Flex drivers delivered packages to private homes and had access to customers’ contact details and information capable of revealing their habits. The Court therefore accepted that verifying candidates’ good standing served the security of the recruitment process and the protection of customers. Accordingly, the Court concluded that the processing was legitimate, granted the controller’s appeal and annulled the DPA’s decision without awarding costs.

### Supreme Court upholds €300,000 fine against INPS for GDPR violations in COVID bonus data

*Source: Supreme Court, 2026-05-21 — https://overview.legal/posts/53097 — original: https://gdprhub.eu/index.php?title=Cass.Civ._-_15625/2026*

Facts — Istituto nazionale della previdenza sociale (INPS, the controller) is the Italian National Institute for Social Security. In 2021, the DPA fined the controller €300,000 for its data processing activities linked to a subsidy given during the pandemic (also called “the COVID bonus”). The DPA found that the controller had postponed its second screening of verifying the eligibility of data subjects to a later stage, on the grounds that there was a need to immediately pay the subsidy. The controller considered that politicians did not fall under the scope of eligible data subjects, as they were already enrolled in a mandatory social security scheme. The controller processed their personal data from databases to cross reference them with data subjects who had applied for the subsidy. The DPA found a violation of several GDPR principles: the principle of lawfulness (Article 5(1)(a) GDPR), data minimisation (Article 5(1)(c) GDPR), accuracy (Article 5(1)(d) GDPR) and accountability (Articles 5(2) and 24 GDPR). According to the DPA, the controller had not limited the cross referencing to data subjects that had received the allowance, but to those whose applications had already been rejected. In addition, the DPA found a violation of Articles 25 and 35 GDPR, as the controller failed to conduct a data protection impact assessment (DPIA). The DPA ordered the controller to erase all personal data that had been processed unlawfully and to carry out a DPIA before resuming its processing activities. The controller appealed the decision to the Court of Rome, and argued that the DPA’s decision was unfounded. The court upheld the appeal and dismissed the DPA’s decision. The court considered that the controller had processed data subjects’ data lawfully, as it had limited the amount of data to what was necessary to verify data subjects’ eligibility. The court also considered that the processing posed a low risk for data subjects’ rights, as the data subjects’ names were not disclosed. The DPA appealed this decision to the court. Holding — The court dismissed the appeal. The court first stated that the controller processed the data lawfully under Article 6(1)(e) GDPR (public interest) and Article 6(3)(b) GDPR. While the controller processed data of specific data subjects (politicians), the court stated that national law allowed the controller to check the eligibility of all data subjects applying for the subsidy. The controller had also obtained the personal data through public databases provided by the Chambers of Parliament and Ministry of the Interior. The court also dismissed the DPA’s arguments on data minimisation (Article 5(1)(c) GDPR). The court stated that the principle of data minimisation is not absolute, and must be balanced with other interests at stake. The court took into consideration the fact that the data was publicly available and the need to quickly verify a high number of applications during a state of emergency. According to the court, there was also no other way to check applications still under review, and concluded that there was an overriding public interest in carrying out the verification process quickly. Finally, the court considered that the controller complied with Article 25 GDPR, as it processed data lawfully and in compliance with Article 5(1)(c) GDPR. In terms of data accuracy (Article 5(1)(d) GDPR), the court dismissed the DPA’s argument that the controller’s system did not eliminate the risk of “homocodes” (identical tax numbers between two or more people). The court considered that the data collected by the Chambers of Parliament and Ministry of Interior were presumed to be accurate. The court also noted that national law foresees the risk of “homocodes” and sets specific procedures in such cases, and that no actual inaccuracies were found in the controller’s verification process. Finally, the court did not find a violation of Article 35 GDPR. The court stated that the controller did not have the obligation to conduct a DPIA, as it did not meet all the necessary criteria. According to the court, the DPA failed to explain the potential high risks of large scale processing that would have justified the need for a DPIA. Given the previous dismissed arguments, the court considered that the controller had also complied with the principle of accountability (Articles 5(2) and 24 GDPR).

### CJEU - C‑371/24 - Comdribus

*Source: GDPRhub, 2026-03-19 — https://overview.legal/posts/125595 — original: https://gdprhub.eu/index.php?title=CJEU_-_C‑371/24_-_Comdribus*

Facts — In 2020, law enforcement officers arrested several people from a climate protest. One of the individuals detained (the data subject) provided their identity, but refused to be fingerprinted and photographed, as well as to provide the code to their phone (or unlock it themselves). The data subject was later accused before the Paris Criminal Court of unlawfully organising a protest, as well as refusing to provide their data for identification and investigation purposes in accordance with national law . The court found them guilty of not providing their biometric data and fined the data subject €300. Both the data subject and Public Prosecutor appealed the decision to the Paris Court of Appeal. The court requested a preliminary ruling from the CJEU, regarding the compatibility of national law with provisions of the Law Enforcement Directive (LED), taking into consideration previous case law . Specifically, the court had questions regarding the systematic processing of biometric data of a data subject reasonably suspected of having committed or attempted to commit an offense in the context of an investigation, when the data subject has not necessarily been accused of committing an offense. The court referred the following questions: 1. Does the Law Enforcement Directive 2016/680 preclude national legislation from systematically processing identification data from data subjects who are suspected of having committed or attempted to commit an offense? 2. Does the Law Enforcement Directive 2016/680 require national legislation to oblige a competent authority to sufficiently explain why it is strictly necessary to process this data on an individual basis? 3. Does the Law Enforcement Directive 2016/680 preclude national legislation from allowing data subjects to be prosecuted on the basis of refusing to provide identification data, even if they are not prosecuted for or convicted of the offense under which said data was processed? The French Government argued that the national law complies with the strict necessity requirements of the LED. For example, the wording of the law leaves the competent authority the discretion to process non-sensitive data for the purposes of the investigation. In addition, national law provisions strictly limit the processing of biometric data for investigation purposes. Finally, the government questioned the admissibility of the second and third questions, arguing that both concerned matters outside the scope of EU law. Holding — Question 1: systematic collection of biometric data under national law — The court first noted that Article 10 Law Enforcement Directive 2016/680 aims to ensure a higher level of protection for personal data that is considered sensitive by nature (e.g. biometric data), as its processing can create significant risks for data subjects’ fundamental rights. Under Article 10 Law Enforcement Directive 2016/680, processing activities allowed under national law must also be strictly necessary in relation to the purposes of processing this data. This also requires the purposes to be sufficiently precise, and the processing activities to be relevant and respects the principle of data minimisation (Article 4(1)(c) Law Enforcement Directive 2016/680). Therefore, Member States must either delegate the responsibility of complying with these requirements to a competent authority, or include assessment criteria in national law for authorities to follow. In this case, the court found that national law is not compatible with the LED in terms of collecting biometric data in an indiscriminate and generalised manner. This is because it provided for the systematic collection of biometric and genetic data of any person accused of an intentional offense with the purpose of entering them in a record, without also obliging competent authorities to demonstrate first that this data processing is strictly necessary. The court stated that the scope of processing biometric data was particularly broad, as it concerned all data subjects reasonably suspected of having committed or attempted to commit a criminal offense. The court took into consideration the possible interferences with data subjects’ fundamental rights . The court concluded that it was for the referring court to determine whether national law required the police authority to carry out a systematic collection of biometric data, and to verify the data subject’s claim of an automated database containing the fingerprints of 6.5 million data subjects. Question 2: obligation of a competent authority to explain the necessity of the data processing — The court first stated that this question was admissible, as it concerned the obligations of a national competent authority in relation to EU law (Article 10 of the LED). The court then noted that the obligation to implement appropriate safeguards when processing biometric data is connected to data subjects’ fundamental right to an effective judicial remedy (Article 47 CFR). Therefore, a competent authority must provide data subjects with information on why it is “strictly necessary” to process their biometric data to allow them to exercise this right. The court stated that this information could be succinct in order to not compromise the investigation. However, the information must also be sufficiently clear. Furthermore, this obligation was essential in ensuring that a competent authority carries a case by case assessment on whether it is “strictly necessary” to process a data subject’s biometric data, as well as allowing national courts to review the competent authority’s decision. This is especially relevant in relation to the competent authority’s obligation to demonstrate compliance with Articles 4(1)(a) to (c) Law Enforcement Directive 2016/680, as it acts as a controller in accordance with Article 3(8) Law Enforcement Directive 2016/680. In any event, this judicial review cannot compensate for cases where the competent authority is not obliged to state the reasons why the data processing is strictly necessary. Finally, the court noted that this obligation is not an excessive burden for the authority, since it was clear that it may not systematically process biometric data of data subjects reasonably suspected of having committed or attempted to commit an offense. Question 3: refusal to provide biometric data as an offense — The court first stated that this question was admissible, as it was not obvious that the facts in dispute bear no relation to EU law. The court clarified that the LED was also applicable to situations in which a competent authority attempts to process personal data. Therefore, if national law imposes a criminal penalty for refusing to provide this data, this penalty is lawful if it complies with the LED (in essence, the processing must meet the conditions of strict necessity in accordance with Article 10 Law Enforcement Directive 2016/680 and Articles 4(1)(a) to (c) Law Enforcement Directive 2016/680 and 8 Law Enforcement Directive 2016/680). The court stated that the LED does not preclude national law allowing data subjects to be prosecuted on the basis of refusing to provide identification data, even if they are not prosecuted for or convicted of the offense under which said data was processed. However, national law must meet the strict necessity requirement under Article 10 Law Enforcement Directive 2016/680, and the criminal penalty must be proportionate. The court noted that fact that a data subject is reasonably suspected of committing an offense or attempted to commit an offense is not in itself decisive to determine whether the data processing is strictly necessary. In addition, the criminal penalty must be proportionate to the offense, and take into account the individual circumstances of each case. The court concluded that it was for the referring court having jurisdiction to impose a criminal penalty to take into consideration the individual circumstances of the case.

### CJEU - Case C‑5/25 - Pilev

*Source: GDPRhub, 2026-03-05 — https://overview.legal/posts/125592 — original: https://gdprhub.eu/index.php?title=CJEU_-_Case_C‑5/25_-_Pilev*

Facts — In September 2023, the Bulgarian Public Prosecutor’s Office brought a criminal case against a data subject to the Sofia City Court. According to the Prosecutor’s Office, the data subject bribed police officers, and worked as a taxi driver without the necessary license. During the proceedings, the court requested personal data from the data subject in order to verify their identity. While a data subject can be identified with their identity card, national law requires national courts to ask further questions to further verify the data subject’s identity. The court had doubts on the compatibility of said national law provisions with the Bulgarian Constitution, and stayed proceedings. In addition, the court had doubts on whether requesting additional information (e.g. place of birth, ethnicity, or marital status) is necessary, and whether the national provisions are consistent with Article 10 Law Enforcement Directive 2016/680. The court referred the matter to the Constitutional Court. The Constitutional Court refused to give a substantive ruling, and the court therefore requested a preliminary ruling from the CJEU. Advocate General Opinion — The AG first stated that the data processing fell in the scope of the LED in accordance with Article 2(1) Law Enforcement Directive 2016/680. The LED is applicable if the data processing is carried out by a competent authority (Article 3(7) Law Enforcement Directive 2016/680) and for the purposes listed in Article 1(1) Law Enforcement Directive 2016/680. The LED is the lex specialis of the GDPR, which excludes from its scope processing of personal data that falls within the scope of the LED. In the AG’s view, the court falls within the definition of a competent authority; while it may not expressly follow the definition of competent authority, it can be inferred from the provisions’ context. The AG also considered that the definition of “prosecution of criminal offenses” can be interpreted broadly, and therefore the court’s processing activities fell under the scope of the LED. This does not contradict the principle that exceptions to the GDPR (as lex generalis) should be interpreted strictly, as criminal court proceedings would not be exempt from data protection regulations. The AG also highlighted that having two different data protection laws apply at different stages of the court proceedings and by different law enforcement actors would lead to a fragmented legal regime, in contradiction to the principle of legal certainty and consistent protection of personal data. Finally, the AG noted that the LED grants law enforcement authorities more flexibility in processing data, particularly in the case of processing sensitive personal data prohibited under Article 9(1) GDPR. In terms of national law provisions, the AG opined that national law requiring the systematic processing of data subjects’ personal data when verifying their identity was not compatible with the LED, when this data is not necessary for that purpose. The purpose of verifying that a data subject is the person being indicted is a legitimate purpose. However, the AG opined that requiring courts to systematically process data such as ethnicity, marital status or previous convictions were not compatible with the principle of data minimisation (Article 4(1)(c) Law Enforcement Directive 2016/680) or lawfulness (Article 8(1) Law Enforcement Directive 2016/680). This is because this information is not necessary at the stage of proceedings of verifying the data subject’s identity. Even in cases where this information was needed, the AG noted that the systematic nature of this data processing was disproportionate. Finally, the AG highlighted that the court would systematically process special categories of personal data, which Article 10 Law Enforcement Directive 2016/680 allows only where strictly necessary. Holding — TBD.

### JH v Policejní prezidium

*Source: CJEU, 2025-11-20 — https://overview.legal/posts/51304 — original: https://www.annaberlee.nl/cjeu/62023CJ0057.pdf*

HvJ EU 20 november 2025, C-57/23, ECLI:EU:C:2025:905, (JH v Policejní prezidium).

### NSA - III OSK 5037/21

*Source: Supreme Administrative Court, 2025-04-29 — https://overview.legal/posts/125644 — original: https://gdprhub.eu/index.php?title=NSA_-_III_OSK_5037/21*

Facts — In March 2020, the Ombudsman requested the DPA to initiate proceedings regarding several laws that introduced an obligation for judges and prosecutors to declare their membership in an association, which would then be included in a Public Information Bulletin. The declarations of membership included associations to churches, religions, political parties, and functions similar to trade unions. The Ombudsman argued that the law was unconstitutional. In addition, the Ombudsman requested that the DPA issue an order restricting the processing of this data, specifically to prohibit the publication in the bulletin until proceedings were complete. The DPA dismissed the case in April 2020. The DPA stated that Article 6(1) GDPR provided a legal basis for the processing based on a legal obligation (Article 6(1)(c) GDPR) and necessity for the public interest (Article 6(1)(e) GDPR). Finally, the DPA stated that it did not have the competence under Article 57 GDPR to decide on the issue of constitutionality; this was a matter the Ombudsman should have taken to the Constitutional Court. The Ombudsman appealed the decision to the Court of First Instance, arguing that the DPA should have also considered whether the law fulfilled the requirements of public interest and proportionality under Article 6(3) GDPR. The Court upheld the reasoning of the DPA, stating that law has a legal basis in accordance with the GDPR. According to the Court, GDPR does not give the DPA broader powers, since the this was not foreseen by the EU legislator or provided by national law. The Ombudsman appealed the case to the Provincial Administrative Court, who dismissed the case. The Ombudsman requested the Court to reconsider, or alternatively, the Supreme Administrative Court. In addition, the Ombudsman requested the Supreme Administrative Court to refer a preliminary question to the EU Court of Justice (CJEU). The Provincial Administrative Court referred the case to the Supreme Administrative Court. In its complaint, the Ombudsman argued there was a violation of EU and national law due to the DPA’s and Court’s failure to act, as well as the law restricting the judges and prosecutor’s freedom of religion and assembly. The Ombudsman cited CJEU Case C-204/21 (European Commission v. Republic of Poland). In this case, the CJEU found that national legislation requiring judges to submit written declarations of membership in a political party violated Article 7 CFR and Article 8 CFR, as well as Article 6(1)(c) GDPR and Article 6(3) GDPR. In addition, the CJEU stated that it was insufficient for a national law to meet the formal criteria (e.g. by specifying the data processed and the storage period), it also needed to meet the qualitative criteria (public interest purpose and proportionality). Holding — The Supreme Administrative Court first dismissed the request of the Ombudsman to refer a preliminary question to the CJEU, on the basis that the case C-204/21 made the question irrelevant. Nonetheless, the Court stated that it had the obligation to take the CJEU case into account in assessing whether a national law is compatible with EU law, regardless of the issues raised in the appeal. Article 260(1) TFEU obliges the Court to take measures to ensure the implementation of a CJEU judgment stating that a Member State has not complied with its obligations under the Treaties. The Court considered that the Court of First Instance had misinterpreted Article 6(1)(c) GDPR and Article 6(1)(e) GDPR by limiting its interpretation to national laws. According to the Court, the decision did not consider the Constitution or the CFREU (Article 8 CFR and Article 10(1) CFR) and the European Convention of Human Rights (ECHR) (Article 8 ECHR and Article 9(1) ECHR and Article 9(2) ECHR ). The Court followed the reasoning of the CJEU in Case C-204/21 and concluded that the Polish law requiring judges and prosecutors to disclose their affiliation with religious, trade union and political organisations was a serious interference of their rights under the CFREU. The Polish law also violated Article 6(1)(c) GDPR and Article 6(1)(e) GDPR and Article 6(3) GDPR. The Court referred to the CJEU's reasoning in stating that the processing and publishing of judges' and prosecutors' personal data is likely to reveal their worldview and religious beliefs. This data belongs to the special category of personal data that has additional protections in accordance with Article 9(1) GDPR. The Court overturned the decision by the lower courts and the DPA.

### Judgment of the Court (First Chamber) of 27 February 2025.#CK v Magistrat der Stadt Wien.#Request for a preliminary ruling from the Verwaltungsgericht Wien.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 15(1)(h) – Automated decision-making, including profiling – Scoring – Assessment of the creditworthiness of a natural person – Access to meaningful information about the logic involved in profiling – Verification of the accuracy of the infor

*Source: Court of Justice of the European Union, C-203/22, 2025-02-27 — https://overview.legal/posts/132146 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0203*

In Case C-203/22, the Court of Justice of the European Union interpreted Article 15(1)(h) of the GDPR in response to a preliminary ruling from the Verwaltungsgericht Wien concerning an individual's request for meaningful information about the logic of creditworthiness scoring conducted by Dun & Bradstreet Austria GmbH. The Court held that data subjects must receive sufficiently detailed explanations of the logic involved in automated profiling to understand how the decision was reached, while controllers may withhold information protected by trade secrets under Directive (EU) 2016/943 only insofar as such withholding does not render the information provided meaningless. The Court further clarified that data subjects may not use access rights to obtain personal data of third parties or to verify the absolute accuracy of the underlying information processed.

## Guidance

### Opinion 11/2024 on the use of facial recognition to streamline airport passengers’ flow (compatibility with Articles 5(1)(e) and(f), 25 and 32 GDPR)

*Source: EDPB, opinion-112024-on-the-use-of-facial-recognition-to-streamline-en, 2024-05-24 — https://overview.legal/posts/125750 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-112024-on-the-use-of-facial-recognition-to-streamline_en*

A dopted Opinion 11/2024 on the use of facial recognition to streamline airport passengers’ flow (compatibility with Articles 5(1)(e) and(f), 25 and 32 GDPR Version 1.1 Adopted on 23 May 20 24 Adopted 1 Version 1.1 28 May 2024 Grammatical correction in the E xecutive summary (pages 3 and 4) and paragraphs 77 and 90 of the Opinion Version 1.0 23 May 2024 Adoption of the Opinion Adopted 2 Executive summary The French Supervisory Authority requested the European Data Protection Board to issue an…

### Opinion 26/2018 on the draft list of the competent supervisory authority of Luxembourg regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

*Source: EDPB, opinion-262018-on-the-draft-list-of-the-competent-supervisory-en, 2018-12-04 — https://overview.legal/posts/126264 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-262018-on-the-draft-list-of-the-competent-supervisory_en*

1 Adopted EDPB Plenary meeting, 04/05.12.2018 Opinion 26 /2018 on the draft list of the competent supervisory authority of Luxembourg regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) Adopted on 4 December 2018 2 Adopted TABLE OF C ONTENTS 1 Summary of the Facts ................................ ................................ ................................ ..................... 4 2 Assessment…

### Opinion 3/2018 on the draft list of the competent supervisory authority of Bulgaria regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

*Source: EDPB, opinion-32018-on-the-draft-list-of-the-competent-supervisory-en, 2018-10-03 — https://overview.legal/posts/126291 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-32018-on-the-draft-list-of-the-competent-supervisory_en*

Opinion 3 /2018 on the draft list of the competent supervisory authority of Bulgaria regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) Adopted on 25th September 2018 2 Contents 1. Summary of the Facts ................................ ................................ ................................ ........ 4 2. Assessment ................................ ................................ ................................…

### Opinion 10/2018 on the draft list of the competent supervisory authority of Hungary regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

*Source: EDPB, opinion-102018-on-the-draft-list-of-the-competent-supervisory-en, 2018-10-03 — https://overview.legal/posts/126282 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-102018-on-the-draft-list-of-the-competent-supervisory_en*

Opinion 10 /2018 on the draft list of the competent supervisory authority of Hungary regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) Adopted on 25th September 2018 2 Contents 1. Summary of the Facts ................................ ................................ ................................ ........ 4 2. Assessment ................................ ................................ ................................…

### Opinion 21/2018 on the draft list of the competent supervisory authority of Slovakia regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

*Source: EDPB, opinion-212018-on-the-draft-list-of-the-competent-supervisory-en, 2018-10-03 — https://overview.legal/posts/126305 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-212018-on-the-draft-list-of-the-competent-supervisory_en*

Opinion 21 /2018 on the draft list of the competent supervisory authority of Slovakia regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) Adopted on 25th September 2018 2 Contents 1. Summary of the Facts ................................ ................................ ................................ ........ 4 2. Assessment ................................ ................................ ................................…

### Guidelines 05/2022 on the use of facial recognition technology in the area of law enforcement

*Source: EDPB, edpb-guidelines-on-the-use-of-facial-recognition technology-in-the-area-of-law-enforcement, 2023-05-17 — https://overview.legal/posts/38075 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-052022-on-the-use-of-facial-recognition-technology-in-the-area-of_en*

More  and  more  law  enforcement  authorities  (LEAs)  apply  or  intend  to  apply  facial  recognition technology (FRT). It may be used to authenticate or to identify a person and can be applied on videos (e.g. CCTV) or  photographs. It may be used for various purposes, including to search for persons  in police watch lists or to monitor a person's movements in the public space. FRT is  built on the processing of biometric data , therefore, it encompasses the processing of special categories ...

### Opinion 11/2018 on the draft list of the competent supervisory authority of Ireland regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

*Source: EDPB, opinion-112018-on-the-draft-list-of-the-competent-supervisory-en, 2018-10-03 — https://overview.legal/posts/126301 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-112018-on-the-draft-list-of-the-competent-supervisory_en*

Opinion 11 /2018 on the draft list of the competent supervisory authority of Ireland regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) Adopted on 25th September 2018 2 Contents 1. Summary of the Facts ................................ ................................ ................................ ........ 4 2. Assessment ................................ ................................ ................................…

### Opinion 5/2018 on the draft list of the competent supervisory authorities of Germany regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

*Source: EDPB, opinion-52018-on-the-draft-list-of-the-competent-supervisory-en, 2018-10-03 — https://overview.legal/posts/126311 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-52018-on-the-draft-list-of-the-competent-supervisory_en*

Opinion 5 /2018 on the draft list of the competent supervisory authorit ies of Germany regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) Adopted on 25th September 2018 2 Contents 1. Summary of the Facts ................................ ................................ ................................ ........ 4 2. Assessment ................................ ................................ ................................…

## Enforcement decisions

### DSB: Medical student fined for recording dementia patient video without Art 9 GDPR basis

*Source: DSB (Austria), 2026-01-12 — https://overview.legal/posts/96832 — original: https://gdprhub.eu/index.php?title=DSB_(Austria)_-_2026-0.016.479*

Facts — A medical student (the controller) worked as a ward attendant at a hospital. Her duties were to remain in the immediate vicinity of patients, ensure their safety and notify the nursing staff immediately when necessary. While assigned to a patient with dementia (the data subject), she recorded a video of him wearing a hospital gown and throwing a newspaper to the floor. She subsequently sent the video to a fellow student through a messaging service. The recording lasted about eleven seconds. Holding — The DPA treated the medical student as the controller of the relevant processing pursuant to Article 4(7) GDPR because she decided to record the data subject and disclose the video to a third party. It found that the context of the video, the data subject’s clothing and behaviour revealed information concerning his health within the meaning of Article 4(15) GDPR. The video therefore contained special categories of personal data. The DPA noted that an applicable condition under Article 9(2) GDPR was required for the processing. The DPA found that the controller lacked a legal basis for the relevant processing. It emphasized that the controller could not rely on Article 6(1)(f) GDPR since Article 9(2) GDPR restricts processing based on legitimate interest. The DPA pointed out that no scientific purpose was apparent for this recording and disclosure. It further noted that the video recording of the data subject was made for the purpose of exchanging comments with a fellow student. It therefore held that the processing also lacked a legitimate purpose under Article 5(1)(b) GDPR. The DPA concluded that the controller infringed Article 5(1)(a) GDPR, Article 5(1)(b) GDPR, Article 6(1) GDPR and Article 9(2) GDPR. It found that she had acted intentionally, as she had knowingly recorded and transmitted the video and was aware that the processing was unlawful. It imposed a fine of €200, with twelve hours’ substitute imprisonment if the fine proved uncollectible.

### APDCAT (Catalonia) - PD 6/2021

*Source: APDCAT (Catalonia), 2021-07-22 — https://overview.legal/posts/125610 — original: https://gdprhub.eu/index.php?title=APDCAT_(Catalonia)_-_PD_6/2021*

Facts — The Catalan DPA issued an opinion at the request of the Ministry of the Interior in order to evaluate the Law proposal that will transpose the Directive (EU) 2019/1153, laying down rules facilitating the use of financial and other information for the prevention, detection, investigation or prosecution of certain criminal offences. Holding — In the about general issues, the DPA pointed out that the law proposal does not clearly state which personal data of the financial ownership file will be accessible for the competent authorities as well as which data will be excluded, and that some necessary definitions are missing. In the next sections, it is pointed out that Article 7(1) does not concur with the principle of data minimization, so a new redaction is proposed. It is also mentioned that a remark regarding that the sharing of information shall be carried out with the implementation of the necessary technical and organizational measures to guarantee the security of the data needs to be added for every article. With regards to the data protection section, the DPA laid down an amendment changing the sentence “when necessary” for “when indispensable”, in order to strengthen the exceptionality for the processing of special categories of personal data. Another amendment remarking the individualization and the technical training of the people who will process the data is lastly suggested.

### IMY reprimands Swedish Police for inadequate GDPR Article 13 info at Arlanda border

*Source: IMY (Sweden), 2026-07-03 — https://overview.legal/posts/57263 — original: https://gdprhub.eu/index.php?title=IMY_(Sweden)_-_IMY-2024-2904*

Facts — The supervisory authority launched an investigation into the border control unit of the national police authority (the controller) at Arlanda Airport concerning the processing of the personal data of travellers arriving from third countries (the data subjects). During border control, the controller scanned the data subjects’ passports, and some travellers were required to provide fingerprints. The data collected was then possibly checked against various border control systems, such as the Schengen Information System (SIS) and the Visa Information System (VIS). There were no signs, brochures, or other written information on the processing of personal data available directly in the arrival hall. The only information available could be found on the controller’s website. Holding — The DPA issued the controller a reprimand for the infringement of Article 13 GDPR. It held that the controller had not provided the data subjects sufficient information about the processing of personal data during border controls. According to the DPA, the data subjects had not been able to easily access information regarding, among other things, what personal data is collected, how it is processed, and what rights data subjects have. The DPA took into account that not all travellers arriving from third countries could be expected to know which national authority is responsible for border controls, let alone be able to find and understand the information on the controller’s website without any guidance in the arrivals hall. It concluded that the lack of easily accessible information on this matter constituted a significant shortcoming: the border control operations included the processing of sensitive data, including biometric data, of a large number of travellers on a daily basis. On the other hand, the investigation was limited to one arrivals hall. The controller had also obtained signs with tailored information regarding the processing of personal data during border control since the beginning of the investigation. Based on an overall assessment, the DPA held that the lack of information required by Article 13 in the arrivals hall constituted a minor GDPR violation.

### Italian DPA: Justice Ministry unlawful disclosure of employee health data in service order

*Source: Garante per la protezione dei dati personali (Italy), 2026-07-20 — https://overview.legal/posts/144019 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_10254256*

Facts — The data subject was an employee at a detention facility run by the Italian Ministry of Justice (the controller). Following an assessment by the occupational health physician, who certified that the data subject was fit for service but had to be exempted from wearing a duty belt and could not hold fixed postures for long periods, the facility issued a service order assigning him to a specific operational unit. The service order referred to the data subject's "physical conditions", his "health needs" and the need for an "alternation of posture". The service order itself provided that a copy would be posted on the institute's noticeboard for publicity purposes. Copies were displayed on the noticeboard located in the bar/canteen area and in the TV/relax area, both accessible to all staff on duty but not to outsiders. Further copies were sent to the head of department, the services office, the coordinator of the records office and the penitentiary police secretariat, as well as to the trade unions, and the document was filed in the official collection of service orders. The data subject filed a complaint with the DPA. During the investigation, the controller argued that the reference to the alternation of posture did not disclose any sensitive data and merely justified the assignment decision to other staff. It also argued that, as an administrative act, the service order had to state the reasons of fact and law behind it under Article 3 of Law 241/1990, that its display and communication to the trade unions followed from transparency rules on administrative acts and from the National Framework Agreement for Penitentiary Police Personnel, and that the data subject had been notified of the order and had not objected at the time. The controller added that the order was replaced on the noticeboard after a short period and that all internal recipients were instructed and authorised to process personal data. Holding — First, the DPA held that the information in the service order constituted health data under Article 4(15) GDPR. The references to the data subject's physical conditions, health needs and the need to alternate his posture related unequivocally to his overall psychophysical state, even without any express diagnosis, and the order had been issued precisely to implement the measures prescribed by the occupational health physician under Article 42 of Legislative Decree 81/2008. The DPA also noted that the reference to the alternation of posture allowed anyone to infer the nature of the data subject's condition. Second, the DPA recalled that an employer may access the fitness-for-duty assessment and the working conditions prescribed by the occupational health physician, but only through staff specifically appointed and authorised to process such data. Making data available to persons who are not authorised to process it, even where they belong to the controller's own organisation, amounts to a communication of personal data that requires a legal basis under Article 2-ter of the Italian Data Protection Code and, for health data, under Article 9 GDPR. The DPA found that the display of the order on a noticeboard accessible to all staff, and its transmission to the trade unions, made the data available to colleagues and third parties who had no need to know it. Access should have been restricted, on strict proportionality grounds, to the staff responsible for actually implementing the measures in the exercise of managerial and organisational functions. Therefore, the DPA found a violation of Articles 5(1)(a), 6 and 9 GDPR and Article 2-ter of the Italian Data Protection Code. Third, the DPA rejected the controller's justification based on the duty to give reasons for an administrative act. The document remained in full in the administration's files and was accessible to anyone demonstrating a direct, concrete and current interest under Articles 22 of Law 241/1990 and Articles 59 and 60 of the Italian Data Protection Code. A generic reference to transparency rules on administrative acts was not sufficient either, since those rules do not provide for disclosure by way of noticeboard display. Fourth, the DPA held that collective agreements cannot constitute an appropriate legal basis for a communication of personal data. Collective agreements may only specify, in favour of employees, a framework already laid down by national legislation and cannot introduce a new processing operation not provided for by law. The DPA added that, even where union prerogatives do entail communications to trade unions, these must comply with the necessity principle and be accompanied by specific safeguards, all the more so where the data concern the most intimate sphere of the person. Finally, the DPA classified the gravity of the violation as medium. It considered that the case concerned a single data subject and that the order remained on the noticeboard for a very short time, but also that the conduct reflected an ordinary practice based on collective agreements. The violation was negligent, as the controller had acted in the mistaken belief that it was complying with the applicable rules. As mitigating factors, the DPA took into account the controller's full cooperation during the investigation and the absence of relevant previous violations at the facility concerned. On these grounds, the DPA fined the controller €12,000.

### HDPA (Greece) examines deletion request from National Registry of Undesirable Aliens

*Source: HDPA (Greece), 2026-05-13 — https://overview.legal/posts/144044 — original: https://gdprhub.eu/index.php?title=HDPA_(Greece)_-_12/2026*

Facts — The complainant, a foreign national, submitted a complaint to the Hellenic DPA through his authorized attorney, seeking his deletion from the Hellenic the National Registry of Undesirable Aliens. In response to the Authority's request for clarifications, the competent Directorate of the Ministry of Citizen Protection informed the DPA that: • By a decision dated 27-07-2017, an entry ban and registration in the National Registry of Undesirable Aliens were imposed on the complainant for reasons of national security. • Following temporary 48-hour lifts of the measure for humanitarian reasons in 2019, the entry ban was re-imposed. • Subsequent decisions in 2020, 2023, and 2025 maintained the entry ban and renewed his registration in the National Registry of Undesirable Aliens for successive three-year periods, as the grounds for registration remained active. • The explicit grounds and documentation behind the registration were not disclosed to the complainant because the competent Directorate classified the file as restricted/classified service material. The complainant and his attorney attended a DPA hearing on 22-04-2026, arguing that the registration lacked specific, adequate, or definitive justification regarding any threat to public order or national security. They noted that the complainant has no criminal convictions, poses no threat, and possesses strong ties, residency, and business operations in the region of Northern Epirus and Greece, meaning the entry ban severely disrupts his professional and family life. Holding — According to the provisions of Article 82(1) of Law 3386/2005, foreign nationals whose presence in Greek territory constitutes a threat to national security, public safety, or public order can be registered in the National Registry of Undesirable Aliens, with registrations subject to an ex officio review every three years. Furthermore, pursuant to the provisions of Article 54(2) and Article 55(4) of Law 4624/2019 (the Greek law implementing the GDPR), the data controller is legally empowered to restrict or omit the provision of information and to deny a data subject access to their personal data when dictated by reasons of national security or public order. These national provisions are explicitly anchored in Article 23 GDPR (specifically Article 23(1)(a)GDPR and Article 23(1)(c) GDPR), which permits Member State law to restrict the scope of the obligations and data subject rights (such as the right to be informed under Article 13 GDPR - Article 14 GDPR and the right of access under Article 15 GDPR) to safeguard national security and public security. In the present case, the evidence demonstrated that the complainant's initial registration and subsequent renewals in the National Registry of Undesirable Aliens were executed lawfully for reasons of national security. The Ministry of Citizen Protection, acting as the data controller, exercised its legal discretion under these frameworks to weigh these interests and correctly determined that the underlying operational decision constitutes classified material that cannot be disclosed to the data subject. Consequently, the fundamental principles of data protection law were not breached, and the Hellenic DPA rejected the complaint as unfounded.

### Austrian DSB: sharing ADHD diagnosis from public forum post did not breach Art. 9 GDPR

*Source: DSB (Austria), 2025-12-03 — https://overview.legal/posts/108990 — original: https://gdprhub.eu/index.php?title=DSB_(Austria)_-_2025-0.968.031*

Facts — A data subject published a post concerning their ADHD diagnosis on a publicly accessible online forum under a pseudonym. A person (the controller) who was a follower of the data subject and had previously been in personal contact with them, knew that the pseudonym belonged to the data subject. The controller subsequently sent a WhatsApp message to a mutual acquaintance stating that the data subject had received an ADHD diagnosis and included a link to the forum post. The data subject lodged a complaint with the Austrian DPA (DSB), arguing that their health data had been disclosed to a third party. They alleged that the controller by forwarding the pseudonymous forum profile, had unequivocally linked it to their real identity. Holding — The DPA held that the data subject was identifiable to the controller as regards the publication of the forum post under her profile name. Since the post also included information concerning her gender, age and diagnosis, it concluded that it constituted her personal data under Article 4(1) GDPR. The DPA further held that the prohibition on processing special categories of personal data under Article 9(1) GDPR did not apply because the data subject had manifestly made their health data public within the meaning of Article 9(2)(e) GDPR. It reasoned that actively disclosing the ADHD diagnosis in a publicly accessible forum constituted an unambiguous and conscious act by which the data subject made the information available to the public. The DPA therefore dismissed the complaint as unfounded.

### Departement of Social Security: Insufficient legal basis for data processing

*Source: Data Protection Authority of Ireland, 2025-06-12 — https://overview.legal/posts/48772 — original: https://www.enforcementtracker.com/ETid-2657*

The Irish DPA imposed a fine of EUR 550,000 on the Departement of Social Security. The controller uses the so called SAFE 2 registration process for anyone applying for a Public Services Card. The SAFE 2 registration, which is mandatory, processes biometric data without a sufficient legal basis. The controller also failed to adequately inform data subjects in regards to the processing and to conduct a data protection impact assessment.

### APD/GBA (Belgium) - 115/2022

*Source: APD/GBA (Belgium), 2022-07-19 — https://overview.legal/posts/6317 — original: https://gdprhub.eu/index.php?title=APD/GBA_(Belgium)_-_115/2022*

Facts — During a meeting where the data subject was not present, the data subject's manager (controller) announced her departure and read out a document issued by the company doctor, stating that she was unfit to work and would leave the company. This statement was also included in the minutes of that meeting. When the data subject discovered this, she filed a complaint against the controller with the Belgian DPA for unlawfully disclosing health related personal data to third parties. She added that the minutes were then saved on the controller´s server, freely accessible to all its staff, including from other departments. Holding — The DPA noted that the data subject did not dispute the lawfulness of processing of the information that she was unfit to work, but the subsequent communication about her health to her colleagues and other staff members. The DPA noted that it was not able to verify whether the minutes were actually made available on the controller's server. However if that were the case, this would amount to an additional processing activity and the following findings of the infringement also apply. The DPA first assessed whether the further processing was compatible with the purpose of the original processing (Article 5(1)(b) GDPR). It found that the purpose of the original processing was personnel management. The DPA held that the data subject could not reasonably expect that the same data would be communicated widely beyond the persons authorised for personnel management. Especially considering the sensitive nature of the data. Therefore the DPA held that the further processing was incompatible with the purpose of the original processing. As the further processing was incompatible with the purpose of the original processing, the DPA noted that it could only be lawful if it had its own legal basis pursuant to Article 9(2) juncto Article 6(1). However the DPA found that this was also not present. Therefore, the DPA held that the controller did not have a proper legal basis for processing the data subject's health related data and thereby violated Article 5(1)(b) juncto Article 6(4) and Article 9(2). The DPA issued a reprimand against the controller. The DPA noted that it was not competent to issue a fine as the controller was a public authority.

## Recent developments

### ICO (UK) - ACRO Criminal Records Office

*Source: GDPRhub, 2026-08-21 — https://overview.legal/posts/291401 — original: https://gdprhub.eu/index.php?title=ICO_(UK)_-_ACRO_Criminal_Records_Office*

The ICO reprimanded ACRO for failing to implement appropriate security measures, including effective patch management and security monitoring, resulting in prolonged unauthorised access to systems containing sensitive personal data. English Summary. Facts. ACRO Criminal Records Office, the processor, is a national police unit providing public services including Police Certificates, International Child Protection Certificates, Subject Access Requests and Record Deletion Requests. It processes per

### DPC (Ireland) - IN-19-9-4

*Source: GDPRhub, 2026-08-18 — https://overview.legal/posts/291263 — original: https://gdprhub.eu/index.php?title=DPC_(Ireland)_-_IN-19-9-4*

The DPA fined the HSE €300,000 for inadequate security measures which enabled a ransomware attack affecting health data of 84,000 people, alongside violations of Articles 28, 30 and 34 GDPR.The DPA fined the HSE €300,000 for inadequate security measures which enabled a ransomware attack affecting health data of 84,000 people, alongside violations of Articles 28, 30 and 34 GDPR. English Summary. English Summary On 8 October 2019, the DPA initiated an own-volition inquiry to determine whether the

### DSB (Austria) - DSB-D124.1749

*Source: GDPRhub, 2026-08-18 — https://overview.legal/posts/291293 — original: https://gdprhub.eu/index.php?title=DSB_(Austria)_-_DSB-D124.1749*

The DPA dismissed the data subject&#039;s complaint about their social security number shared with a financial service provider to obtain financial aid from the controller as it was only used as an identifier and was therefore not considered sensitive. English Summary. Facts. The controller shared the data subject&#039;s social security number with a financial service provider in order to provide financial aid, to which the data subject did not consent. On 17.02.2020, the data subject lodged a c

### ANSPDCP (Romania) - AMATO BESTSELLER S.R.L.

*Source: GDPRhub, 2026-08-18 — https://overview.legal/posts/291260 — original: https://gdprhub.eu/index.php?title=ANSPDCP_(Romania)_-_AMATO_BESTSELLER_S.R.L.*

The DPA imposed a 54,300 fine to a controller for violations of Article 32(4), Article 14 and Article 5(1)(c) in conjunction with Article 9 GDPR and ePrivacy Directive.The DPA imposed a RON 285,395 (€54,300) fine on a wholesale company for, amongst others, failing to implement appropriate security measures, allowing former employees to access personal data as well as for unlawfully using automated dialing and communication systems to call a significant number of data subjects. English Summary. E

### No action taken against PimEyes: noyb lawsuit against Hamburg DPA

*Source: noyb - European Center for Digital Rights, 2026-04-30 — https://overview.legal/posts/53128 — original: https://noyb.eu/en/no-action-taken-against-pimeyes-noyb-lawsuit-against-hamburg-dpa*

National Administrative Procedures and DPA inactivity Today, noyb has filed a lawsuit against the Hamburg data protection authority (DPA). While the authority considers the practices of the facial recognition search engine PimEyes to be illegal, it refuses to take effective action because the company seems to be based in Dubai. PimEyes systematically extracts biometric data from images on the internet and uses it to build up a database. Users can upload photos of people to this website to find f

## Literature

### Recommendations for Creating Codes of Conduct for Processing Personal Data in Biobanking Based on the GDPR art.40

*Source: Frontiers in Genetics, 2021-11-12 — https://overview.legal/posts/132560 — original: https://doi.org/10.3389/fgene.2021.711614*

Personal data protection has become a fundamental normative challenge for biobankers and scientists researching human biological samples and associated data. The General Data Protection Regulation (GDPR) harmonises the law on protecting personal data throughout Europe and allows developing codes of conduct for processing personal data based on GDPR art. 40. Codes of conduct are a soft law measure to create protective standards for data processing adapted to the specific area, among others, to bi

### Criminal Offence and Health Condition Information as Special Categories of Data, and the Legal Aspects of Processing in Labor Relations under GDPR and Georgian Law

*Source: ORBELIANI LAW REVIEW, 2025-03-11 — https://overview.legal/posts/132538 — original: https://doi.org/10.52340/olr.2024.03.01.05*

71 Orbeliani Law Review  Vol. 3, No. 1, 2024 Simoni Takashvili* ORCID: 0000-0001-8608-170X Criminal Offence and Health Condition Information as Special Categories of Data, and the Legal Aspects of Processing in Labor Relations under GDPR and Georgian Law ABSTRACT Criminal offence and health condition information as special categories of data present significant legal challenges in labor relations. The new Personal Data Protection Law outlines the general regulations regarding criminal offence and health condition information as special categories of personal data. The prin - ciples governing the processing of this personal information are very specific, and depend on several factors, especially in employment contexts. Employers have access to private data related to candidates during the pre-contractual phase, and to employees during the contractual relationship. This access car - ries a high risk of breaching the principles of processing special categories of personal data. This article provides a comprehensive analysis of the processing of criminal of - fence and health condition information as special categories of data by the em - ployer. This issue is analyzed within the cont

### If it ain’t broke, don’t fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation

*Source: Computer law & security review, 2026-01-23 — https://overview.legal/posts/53843 — original: https://doi.org/10.1016/j.clsr.2025.106251*

As the General Data Protection Regulation (GDPR) approaches its tenth anniversary, the European legislator is considering reforms thereto. This article offers a set of research-based suggestions for what such reforms could look like, based on two assumptions. First, that the GDPR is overall a solid piece of legislation that upholds the enduring objectives and principles of data protection law. Second, that any improvement cannot compromise the level of protection of fundamental rights currently

### Pilot project lighthouse: A proposed GDPR compliant methodology for analysing special categories of personal data

*Source: Journal of Data Protection Privacy, 2023-10-01 — https://overview.legal/posts/132532 — original: https://doi.org/10.69554/iodl4070*

The General Data Protection Regulation (GDPR) is designed, in part, to prevent discrimination in algorithmic decision making. However, the GDPR's requirements, as well as EU member states' implementing laws, often make testing for bias using special categories of data, such as race, either impractical or impossible. This paper argues that the pilot project lighthouse methodology is a GDPR compliant method for bias-testing special categories of data in algorithms. This paper finds that the pilot

### GDPR: A new challenge for personal data protection

*Source: Bankarstvo, 2017-01-01 — https://overview.legal/posts/132473 — original: https://doi.org/10.5937/bankarstvo1704166m*

stručni članak Erne Mraznica Raiffeisen banka ad Beograd erne.mraznica@raiffeisenbank.rs GDPR - NOVI IZAZOV ZAŠTITE PODATAKA O LIČNOSTI Rezime Dana 4. maja 2016. godine objavljena je Opšta Uredba o zaštiti podataka o ličnosti u Sl. glasniku EU, koja će se primenjivati od 25. maja 2018. godine. Cilj propisa je harmonizacija zaštite podataka o ličnosti na nivou EU, veći stepen kontrole za lica čiji se podaci obrađuju i unapređeno upravljanje savremenim rizicima iz ove oblasti. Banke, po prirodi svog poslovanja, spadaju među najveće rukovaoce podataka o ličnosti i u postupku usklađivanja sa obavezama utvrđenih Uredbom biće u prilici da izvrše punu analizu svog postojećeg regulatornog i infrastrukturnog okvira zaštite podataka o ličnosti. Istovremeno, pruža im se prilika da isprave eventualne nedostatke u postojećim procesima, odnosno da značajno povećaju svest organizacije o standardima zaštite podataka o ličnosti, posebno imajući u vidu zaprećene stroge sankcije za slučaj neusklađenosti. Ključne reči : GDPR, podatak o ličnosti, osnovni principi, prava lica, rukovalac, obrada podataka, transfer podataka, sankcije, usklađivanje JEL : F52, G14 doi: 10.5937/bankarstvo1704166M 166 Bankars

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Types of Special Categories of Personal Data** — https://overview.legal/topics/special-categories-data-types
  A dedicated topic is needed to comprehensively cover the specific types and definitions of special categories of personal data, including racial/ethnic origin, 
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Healthcare** — https://overview.legal/topics/zorg
  Processing of health data and medical information
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Health Data** — https://overview.legal/topics/health-data
  Processing of health and medical data

---
Generated by overview.legal · https://overview.legal/topics/bijzondere-persoonsgegevens · 2026-08-22
